Privacy Notice / KVKK
CertM8 Privacy and Offline Activation Notice
Last updated: July 2026
This notice explains what CertM8 does locally, what it does not automatically send, and what information may be involved during activation, licensing, support, website contact, and normal use.
CertM8 is an offline-first Windows desktop administration tool for IIS and SSL/TLS certificate management.
1. Data Controller
For personal data manually provided during licensing, activation, purchase, support, contact forms, email communication, or other communications, the data controller is the individual owner/operator of CertM8, operating under the brand name Magister Operum.
Magister Operum and CertM8 are brand/product names. If CertM8 is later operated through a registered company, sole proprietorship, or other legal entity, this notice should be updated with the full legal identity and contact details of that entity.
2. Website Contact Form and Server Logs
If you use the website contact form, the website may process the name, email address, subject, and message content you provide.
The website may also process basic technical data such as IP address for contact form rate limiting, spam prevention, abuse prevention, and hosting security. Hosting infrastructure may generate ordinary server logs as part of normal website operation.
Contact form data is used to respond to your inquiry, handle support, manage licensing communication where relevant, and protect the website against abuse.
3. No Automatic Telemetry
CertM8 does not automatically send telemetry, analytics, usage logs, server inventory, IIS data, certificate contents, credentials, passwords, PFX passwords, certificate private keys, server names, IP addresses, usernames, or administrator credentials to Magister Operum.
CertM8 does not automatically upload your certificates, IIS configuration, bindings, server list, or action history to Magister Operum.
CertM8 does not include automatic cloud activation.
4. Offline Activation
CertM8 uses offline activation and local license validation.
When activation is needed, CertM8 may generate an activation request code. The user manually copies this request code and sends it to Magister Operum or an authorized license issuer.
The activation request code is intended only to identify the CertM8 installation or license request. It is not intended to include:
- Windows usernames
- administrator passwords
- PFX passwords
- certificate private keys
- certificate contents
- IIS configuration data
- IIS binding data
- website contents
- server inventories
- server credentials
- domain credentials
- IP address lists
- remote server passwords
Nothing is transmitted automatically. Any activation request code is shared manually by the user.
5. Local License and Settings Files
CertM8 may create local files on the computer for license validation, device binding, server roster enforcement, settings, preferences, and application state.
These files may be stored in Windows application data locations, including:
- ProgramData / common application data
- LocalAppData / user application data
These files may include license state, device-binding state, server roster data, user interface preferences, muted/unmuted interface state, theme selection, puzzle progress, and similar application data.
These files are required for CertM8 to operate correctly.
6. Server Roster Data
CertM8 may store a local licensed server roster.
The roster is used to enforce server limits associated with the license.
The roster may include server names entered or imported by the user.
The roster is stored locally. CertM8 does not automatically transmit the roster to Magister Operum.
7. Certificates and Credentials
CertM8 may interact with certificates, PFX files, certificate stores, IIS bindings, and remote servers when the user chooses those actions.
CertM8 may temporarily use information entered by the user, such as a PFX password, to perform a selected certificate operation.
CertM8 is not intended to transmit PFX passwords, certificate private keys, administrator credentials, or certificate contents to Magister Operum.
Users are responsible for protecting certificates, private keys, passwords, credentials, and exported files.
8. Remote Server Operations
CertM8 may use Windows, PowerShell, WinRM, IIS, certificate store, and HTTP.SYS functionality to query or modify remote servers when the user initiates actions.
These operations happen between the user’s computer and the selected servers according to the user’s Windows permissions, network configuration, PowerShell configuration, WinRM configuration, and IIS configuration.
Magister Operum does not receive the remote server query results unless the user manually shares them during support or troubleshooting.
9. Support Communications
If you contact Magister Operum for support, you may choose to provide information such as:
- your name
- company name
- license key or license status
- activation request code
- screenshots
- error messages
- diagnostic text
- server names
- configuration details
- logs
- email address
- support messages
Only send information you are authorized to share.
Do not send administrator passwords, PFX passwords, certificate private keys, production secrets, private customer data, or confidential infrastructure details unless explicitly required and safely handled through an agreed secure method.
10. SRCASTR Interface Feature
CertM8 includes a cosmetic interface feature known as SRCASTR.
SRCASTR may display sarcastic, humorous, fictionalized, dramatic, insulting, or machine-personality-style messages during certain actions.
SRCASTR messages are decorative interface text only. They are not telemetry, diagnostics, professional advice, security advice, legal advice, operational recommendations, or support instructions.
SRCASTR messages do not change what data CertM8 collects, stores, sends, or processes.
SRCASTR can be muted or suppressed from within the application where that option is available.
11. Payment and Third-Party Services
If CertM8 is purchased through a third-party payment platform, donation platform, storefront, marketplace, payment processor, or similar service, that third party may process payment-related data according to its own privacy policy and terms.
Magister Operum does not control the internal privacy practices of third-party payment providers.
12. Transfers to Third Parties
Magister Operum may share personal data manually provided by the user or customer only where necessary for legitimate business, licensing, support, payment, accounting, legal compliance, dispute handling, fraud prevention, or service operation purposes.
Such recipients may include payment processors, storefronts, accounting providers, email providers, hosting providers, legal or tax advisors, public authorities where legally required, and other service providers used for product, support, or business operations.
Some third-party service providers may be located outside Türkiye or may process data through systems outside Türkiye. Where applicable law requires it, Magister Operum will handle such transfers according to applicable personal data protection rules.
13. Legal Basis for Processing Personal Data
Where Turkish personal data protection law applies, Magister Operum may process personal data manually provided by the user or customer based on one or more legal grounds under applicable law, including:
- processing necessary for establishing or performing a contract, including licensing, activation, purchase handling, support, and customer communication
- processing necessary for compliance with legal obligations, including accounting, tax, invoicing, legal recordkeeping, and dispute handling
- processing necessary for legitimate interests, including fraud prevention, license abuse prevention, product security, support history, and business recordkeeping, provided that such interests do not override the fundamental rights and freedoms of the data subject
- explicit consent, where required by applicable law, including for optional marketing communications or other processing activities that require consent
CertM8 itself is designed not to automatically transmit local server, certificate, IIS, credential, or roster data to Magister Operum.
14. Data Retention
Local CertM8 data remains on the installed computer until the user, administrator, uninstaller, or system cleanup process removes it.
Some license, device, or roster data may be deliberately preserved during uninstall to prevent accidental license loss, activation abuse, or roster reset abuse.
Support emails and support records may be retained as needed for customer support, licensing, fraud prevention, business records, legal compliance, and dispute handling.
Website contact form rate-limit records are temporary and used to reduce repeated submissions. Hosting logs may be retained by the hosting provider according to its own technical and legal requirements.
15. Cookies and Tracking
This website does not intentionally use analytics cookies, advertising cookies, or tracking pixels. If analytics, advertising, embedded third-party widgets, or cookie-based tools are added later, this notice should be updated before those features are released.
16. Security
CertM8 is designed for local/offline licensing and administrative use. However, no software or internet-based system can guarantee perfect security.
Users are responsible for:
- protecting access to the computer
- protecting administrator accounts
- protecting certificates and private keys
- protecting PFX files and passwords
- controlling access to local application data
- securing remote management channels
- following internal security and change-control procedures
17. User Rights and Contact
Where Turkish personal data protection law applies, data subjects may have rights under Article 11 of Law No. 6698, including the right to:
- learn whether personal data is processed
- request information if personal data has been processed
- learn the purpose of processing and whether the data is used in accordance with that purpose
- know the third parties to whom personal data is transferred domestically or abroad
- request correction of incomplete or inaccurate personal data
- request deletion or destruction of personal data where applicable
- request notification of correction, deletion, or destruction to third parties to whom the data was transferred, where applicable
- object to results produced against the person by analysis of processed data exclusively through automated systems
- request compensation for damages caused by unlawful processing
Requests about personal data may be sent to:
Magister Operum may request reasonable information to verify the requester’s identity before responding to a personal data request.
18. Changes to This Notice
This notice may be updated from time to time.
If CertM8 later adds online activation, telemetry, analytics, automatic update checks, crash reporting, cloud services, online account login, or automatic data submission, this notice should be updated before those features are released.
By installing or using CertM8, you acknowledge that you have read this privacy and offline activation notice.